What the vulnerability does
01Description
Missing Authorization vulnerability in kamleshyadav CF7 7 Mailchimp Add-on CF7-mailchimp-addon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CF7 7 Mailchimp Add-on: from n/a through < 2.4.
Explanation of Vulnerability in Simple Terms
02Summary
The CF7 7 Mailchimp Add-on through version 2.4 lacks proper authorization checks, allowing unauthenticated attackers to modify data via the network. The vulnerability does not require user interaction or special conditions. Site administrators should update to a version newer than 2.4 to prevent unauthorized changes to contact forms or Mailchimp integration settings.
What an attacker can do
03Attacker Capabilities
Modify form data or Mailchimp settings without authentication.
Potential impact on your site
04Site Impact
Attackers can alter contact form submissions or Mailchimp integration without logging in.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
July 4, 2025
CVE published
April 28, 2026
Record updated